Menu

Monthly Archives: January 2026

Compose Multiplatform brings auto-resizing to interop views
New Linux malware targets the cloud, steals creds, and then vanishes
Output from vibe coding tools prone to critical security flaws, study finds
Your personal information is on the dark web. What happens next?

If your data is on the dark web, it’s probably only a matter of time before it’s abused for fraud or account hijacking. Here’s what to do.

France fines telcos €42M for sub-par security prior to 24M customer breach
Chinese AI firm trains state-of-the-art model entirely on Huawei chips
‘Imagination the limit’: DeadLock ransomware gang using smart contracts to hide their work
Cyber-stricken Belgian hospitals refuse ambulances, transfer critical patients
Eurail passengers taken for a ride as data breach spills passports, bank details
UK backtracks on digital ID requirement for right to work
Spanish power giant sparks breach probe amid claims of massive data grab
Rust slow to compile? Here’s how to speed it up
When writing code is no longer the bottleneck
Anthropic expands Claude Code beyond developer tasks with Cowork

Viral Vaghela discovered an SQL injection vulnerability in Parsl, a parallel scripting library for Python. For the stable distribution (trixie), this problem has been fixed in version 2025.01.13+ds-1+deb13u1. We recommend that you upgrade your python-parsl packages.

Anthropic finds $1.5 million to help Python Foundation improve security

Version 2.9.3 – 2025-12-30 Security: Fixed ANSI sequence injection (GHSA-59pp-r3rg-353g / CVE-2025-67746) Fixed COMPOSER_NO_SECURITY_BLOCKING env var not being respected for updates done via the install command, and added –no-security-blocking flag to install as well (#12677)

New upstream release (147.0)

Update to 2.69.0

Update to Upstream version 0.1.2 – https://github.com/complytime/complyctl/releases/tag/v0.1.2

Version 2.9.3 – 2025-12-30 Security: Fixed ANSI sequence injection (GHSA-59pp-r3rg-353g / CVE-2025-67746) Fixed COMPOSER_NO_SECURITY_BLOCKING env var not being respected for updates done via the install command, and added –no-security-blocking flag to install as well (#12677)

Windows info-disclosure 0-day bug gets a fix as CISA sounds alarm

https://security-tracker.debian.org/tracker/DSA-6099-1

https://security-tracker.debian.org/tracker/DSA-6098-1

Java 27 gets its first feature
Popular Python libraries used in Hugging Face models subject to poisoned metadata attack
AI and automation could erase 10.4 million US roles by 2030
Dutch cops cuff alleged AVCheck malware kingpin in Amsterdam
Federal agencies told to fix or ditch Gogs as exploited zero-day lands on CISA hit list
Google’s Universal Commerce Protocol aims to simplify life for shopping bots… and devs
Mandiant open sources tool to prevent leaky Salesforce misconfigs

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves one vulnerability and contains one feature can now be installed.

An update that solves one vulnerability can now be installed.

Court tosses appeal by hacker who opened port to coke smugglers with malware

Google Guest Agent could be made to crash if it received specially crafted network traffic.

Britain goes shopping for a rapid-fire missile to help Ukraine hit back
From distributed monolith to composable architecture on AWS: A modern approach to scalable software
Hackers get hacked, as BreachForums database is leaked
Which development platforms and tools should you learn now?
Why hybrid cloud is the future of enterprise platforms
Oracle unveils Java development plans for 2026
India demands crypto outfits geolocate customers, get a selfie to prove they’re real
No fire sale for firewalls as memory shortages could push prices higher
‘Violence-as-a-service’ suspect arrested in Iraq, extradition underway
AI is causing developers to abandon Stack Overflow
Stack thinking: Why a single AI platform won’t cut it
Businesses in 2026: Maybe we should finally look into that AI security stuff
Block CISO: We red-teamed our own AI agent to run an infostealer on an employee laptop
Postman snaps up Fern to reduce developer friction around API documentation and SDKs
Infamous BreachForums forum breached, spilling data on 325K users
Ofcom officially investigating X as Grok’s nudify button stays switched on
Tories vow to boot under-16s off social media and ban phones in schools

Several security issues were fixed in PHP.

How to succeed with AI-powered, low-code and no-code development tools
Why ‘boring’ VS Code keeps winning

Several security issues were fixed in libheif.

India’s government denies it plans to demand smartphone source code
Malaysia and Indonesia block X over failure to curb deepfake smut

Update to 143.0.7499.192 * High CVE-2026-0628: Insufficient policy enforcement in WebView tag * Enable control flow integrity support for x86_64/aarch64 * Enable build for epel10.1

This update adds a patch to fix CVE-2025-56225, a flaw in the bundled version of fluidsynth.

Meta admits to Instagram password reset mess, denies data leak
What Is a WAF? A Linux Security Admins Practical Guide

MGASA-2026-0006 – Updated zlib packages fix security vulnerability

MGAA-2026-0004 – Updated nvidia470 packages fix bug

Update to 143.0.7499.192 * High CVE-2026-0628: Insufficient policy enforcement in WebView tag * Enable control flow integrity support for x86_64/aarch64 * Enable build for epel10.1

Backport fix for CVE-2025-22921

Version 1.0.21 This point release includes all the changes from 1.0.20-stable, which include a security fix for the crypto_core_ed25519_is_valid_point() function, as well as two new sets of functions: The new crypto_ipcrypt_* functions implement mechanisms for securely

Backport fix for CVE-2025-64512 / GHSA-wf5f-4jwr-ppcp

https://security-tracker.debian.org/tracker/DSA-6097-1

UK government exempting itself from flagship cyber law inspires little confidence

MGASA-2026-0005 – Updated libpcap packages fix security vulnerability

MGASA-2026-0004 – Updated sodium packages fix security vulnerability

MGASA-2026-0003 – Updated curl packages fix security vulnerabilities

MGASA-2026-0002 – Updated wget2 packages fix security vulnerability

A security issue was discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), this problem has been fixed in version 143.0.7499.192-1~deb12u1.

MariaDB 10.11.15 Release notes: server/10.11/10.11.15

Visual Studio Code adds support for agent skills

https://security-tracker.debian.org/tracker/DSA-6096-1

How hackers are fighting back against ICE surveillance tech
Credential stuffing: What it is and how to protect yourself

Reusing passwords may feel like a harmless shortcut – until a single breach opens the door to multiple accounts

Putinswap: France trades alleged ransomware crook for conflict researcher
QR codes a powerful new phishing weapon in hands of Pyongyang cyberspies
China-linked cybercrims abused VMware ESXi zero-days a year before disclosure

An update that solves one vulnerability can now be installed.

Grok told to cover up as UK weighs action over AI ‘undressing’
pcTattletale founder pleads guilty in rare stalkerware prosecution

An update that solves one vulnerability can now be installed.

An update that solves one vulnerability can now be installed.

Help desk read irrelevant script, so techies found and fixed their own problem
As agents run amok, CrowdStrike’s $740M SGNL deal aims to help get a grip on identity security

Several security issues were fixed in Tornado.

GnuPG could be made to crash or run programs if it received specially crafted network traffic.

GnuPG could be made to crash or run programs if it received specially crafted network traffic.

Patch Cisco ISE bug now before attackers abuse proof-of-concept exploit
Databricks says its Instruction Retrieval offers better AI answers than RAG in the enterprise
Ransomware attacks kept climbing in 2025 as gangs refused to stay dead
CISA flags actively exploited Office relic alongside fresh HPE flaw